Daily Recap, cybersecurity incidents this week spanned outages in France affecting La Poste and banking services, a Romania ransomware impact on around 1,000 systems, and a disruptive Kuaishou attack that slammed livestreaming and stock prices. It also flags backdoor activity such as the Nezha Trojan, WebRAT distribution via fake GitHub repos, credential-stealing Chrome extensions and a large npm package, plus major enforcement actions, data breaches, a critical n8n flaw, and policy shifts from Microsoft, ServiceNow, the FCC, Japan, and Italy. #LaPoste #Kuaishou #NezhaTrojan #WebRAT #ChromeExtensions #NPMStealer #Frogblight #INTERPOL #FraudDomainSeizure #FakeIDDomains #Nissan #ShinhanCard #UniversityOfPhoenix #n8n #Teams #Armis #FCCDroneBan #JapanStrategy #AppleFine #PasswdWalkthrough #ServiceNowDeal
Outages & Ransomware
- Cyberattack knocked offline France postal and banking services during the Christmas rush, disrupting transactions and operations β La Poste Outage, La Poste Outage, La Poste Outage
- A ransomware attack compromised around 1,000 systems in Romanian Waters, impacting operations β Romania Ransomware
- Cyberattack on Kuaishou disrupted livestreaming and triggered a sharp stock decline for the company β Kuaishou Attack
Malware & Supply-Chain Abuse
- Attackers are abusing the monitoring tool Nezha as a stealth backdoor/trojan for persistence and remote access β Nezha Trojan
- WebRAT malware is being distributed via fake vulnerability-exploit repos on GitHub to deliver backdoors and steal data β WebRAT Malware
- Malicious Chrome extensions that steal user credentials and an NPM package with 56,000 downloads that exfiltrates WhatsApp data were discovered in the wild β Malicious Extensions, NPM Stealer
- Frogblight Android malware poses as fake court and aid apps to trick users and harvest sensitive information β Frogblight Android
Law Enforcement Actions
- INTERPOL-led operations resulted in 574 arrests across Africa and the seizure of roughly $3 million targeting organized cybercrime rings β Interpol Crackdown, Interpol Crackdown
- U.S. authorities seized fraud domains and a password database tied to a massive bank-account takeover scheme that facilitated about $14.6 million in fraud β Fraud Domain Seizure, Password DB Seizure
- The FBI seized Bangladeshi-hosted domains offering fake U.S. ID templates used to facilitate identity fraud β Fake ID Domains
Breaches & Exposures
- Nissan confirmed it was impacted by the Red Hat data breach, potentially exposing corporate information β Nissan Impact
- South Koreaβs Shinhan Card data breach affected roughly 192,000 merchants after unauthorized access to payment systems β Shinhan Breach
- The University of Phoenix data breach affected about 3.5 million individuals after unauthorized exposure of records β Phoenix Breach
Vulnerabilities
- A critical n8n vulnerability (CVSS 9.9) enables arbitrary code execution across thousands of instances and requires immediate patching β n8n Flaw
Policy & Industry
- Microsoft will enable stronger messaging security by default in January for Teams to reduce high-risk sharing and improve protection β Teams Security
- ServiceNow agreed to acquire Armis for $7.75 billion in cash to expand its security and asset-visibility offerings β ServiceNow Deal
- The FCC banned certain foreign-made drones and key parts, citing U.S. national security risks associated with supply chains and devices β FCC Drone Ban
- Japan adopted a new five-year cybersecurity strategy to counter rising cyber threats and strengthen national resilience β Japan Strategy
- Italy fined Apple $116 million over App Store tracking and privacy-practice violations affecting usersβ data rights β Italy Fine
- Guide: a walkthrough of Google Workspace Password Manager (βPasswdβ) explains admin controls and user workflows for credential management β Passwd Walkthrough